AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company has an on-premises data center connected to AWS through a Site-to-Site VPN. Applications on-prem must resolve the private Route 53 records of a VPC-based domain (corp.internal). Which configuration will enable name resolution without exposing the VPC to the internet?
Create a Route 53 Resolver outbound endpoint in the VPC and add a forwarding rule sending corp.internal queries to the on-premises DNS server.
Create a Route 53 Resolver inbound endpoint in the VPC and configure the on-premises DNS server with a conditional forwarder for corp.internal that points to the endpoint's IP addresses.
Associate the private hosted zone with the default VPC and update the VPC DHCP options set to use AmazonProvidedDNS.
Deploy an Interface VPC Endpoint for Route 53 and allow inbound TCP/UDP 53 from the data center.
To let external networks query a private hosted zone, you must create a Route 53 Resolver inbound endpoint inside the VPC. The endpoint provides one or more IP addresses that can be reached over the VPN. Configure the on-premises DNS server with a conditional forwarder (or stub zone) for corp.internal that targets those IPs. Outbound endpoints work in the opposite direction (from the VPC to outside). Updating the VPC DHCP options or deploying an interface endpoint does not give on-prem servers a path to the private zone, and Route 53 has no interface VPC endpoint.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Route 53 Resolver inbound endpoint?
Open an interactive chat with Bash
What is the role of a conditional forwarder in DNS configuration?
Open an interactive chat with Bash
Why can't outbound endpoints or DHCP options be used for on-prem DNS resolution?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .